← back
CVE-2020-24186critical

CVE-2020-24186

85Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 10epss 95%
from disclosure to weapon287 days
Published on NVDAug 24
1st PoC+287d
metasploitFeb 21
exploitation probability
95%top 1% of all CVEs
observed exploitation
nono source reports it
11 public exploit(s)
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allows unauthenticated users to upload any type of file, including PHP files via the wmuUploadFiles AJAX action.
CVSS:3.1/AC:L/AV:N/A:H/C:H/I:H/PR:N/S:C/UI:N
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.